Alerts This Week
Warning Icon 1 1,111
Alerts This Week
Warning Icon 1 1,111

Ubuntu 25.10 libssh Critical Denial of Service Vulnerability USN-8093-1

ubuntu
Calendar Grey March 17, 2026
Dist Ubuntu Esm H88
libssh for Ubuntu has a critical flaw leading to unexpected behavior or crashes. Immediate updates are recommended to mitigate risks.
libssh could be made to crash or behave unexpectedly.

Summary

libssh could be made to crash or behave unexpectedly.

Software Description:

- libssh: A tiny C SSH library

Details:

It was discovered that libssh incorrectly performed bounds checking when

processing SFTP extensions. If a client application queried extension data out

of bounds, it could cause the application to crash, resulting in a denial of

service, or exhibit unintended behavior.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  libssh-4                        0.11.2-1ubuntu0.3

Ubuntu 24.04 LTS
  libssh-4                        0.10.6-2ubuntu0.4
  libssh-gcrypt-4                 0.10.6-2ubuntu0.4

Ubuntu 22.04 LTS
  libssh-4                        0.9.6-2ubuntu0.22.04.7
  libssh-gcrypt-4                 0.9.6-2ubuntu0.22.04.7

Ubuntu 20.04 LTS
  libssh-4                        0.9.3-2ubuntu2.5+esm4
                                  Available with Ubuntu Pro
  libssh-gcrypt-4                 0.9.3-2ubuntu2.5+esm4
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libssh-4                        0.8.0~20170825.94fa1e38-1ubuntu0.7+esm7
                                  Available with Ubuntu Pro
  libssh-gcrypt-4                 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm7
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libssh-4                        0.6.3-4.3ubuntu0.6+esm5
                                  Available with Ubuntu Pro
  libssh-gcrypt-4                 0.6.3-4.3ubuntu0.6+esm5
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8093-1

CVE-2026-3731

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8093-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here